Back to skill

Security audit

sn-infographic

Security checks across malware telemetry and agentic risk

Overview

This skill coherently generates infographics using disclosed model-service calls, with no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable with infographic requests and generated images being processed through the configured sn-image-base model services. Avoid submitting secrets or confidential business data unless your Sensenova/internal model configuration permits that use, and specify a style explicitly when cultural or brand representation matters.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger set includes broad phrases like 'diagram', 'visual summary', and 'data visualization', which can cause the skill to activate for many generic requests outside its intended scope. In an agentic environment, overbroad activation increases the chance of unintended tool use, unnecessary network calls, and routing sensitive user content into this skill when a safer or more appropriate skill should have handled the request.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly sends user prompts, generated content, and image-review inputs to networked model services, including internal services, yet provides no user-facing disclosure or consent warning. This creates a privacy and data-governance risk because users may unknowingly submit confidential text, URLs, or images to remote services under API-key-backed authentication.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The rules automatically map 'Chinese domain' to `chinese-guochao` and 'Japanese domain' to `ukiyo-e`, which hard-codes cultural styling based on inferred locale rather than explicit user preference. This can produce biased or stereotyped outputs, misrepresent user intent, and create trust or compliance issues in professional publishing contexts.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
85% confidence
Finding
The trigger '图解' is very short and semantically broad, so it may match many ordinary requests for explanation or illustration rather than infographic generation specifically. This raises the likelihood of accidental activation and unintended downstream tool execution, though the security impact is limited compared with direct injection or code-execution flaws.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.